CVE-2023-54146
published 2025-12-24CVE-2023-54146: In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix double-free of elf header buffer After b3e34a47f989 ("x86/kexec: fix memory…
PriorityP417medium6.4
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Fix double-free of elf header buffer
After
b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"),
freeing image->elf_headers in the error path of crash_load_segments()
is not needed because kimage_file_post_load_cleanup() will take
care of that later. And not clearing it could result in a double-free.
Drop the superfluous vfree() call at the error path of
crash_load_segments().
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.7-1 (bookworm) | linux 6.1.7-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 23cf39dccf7653650701a6f39b119e9116a27f1a < 4c71a552b97fb4f46eb300224434fe56fcf4f254 | 4c71a552b97fb4f46eb300224434fe56fcf4f254 |
| linux | linux | >= 5.15.46 < 5.15.87 | 5.15.87 |
| linux | linux | >= 5.17.14 < 5.18 | 5.18 |
| linux | linux | >= 5.18.3 < 5.19 | 5.19 |
| linux | linux | >= 8765a423a87d74ef24ea02b43b2728fe4039f248 < 554a880a1fff46dd5a355dec21cd77d542a0ddf2 | 554a880a1fff46dd5a355dec21cd77d542a0ddf2 |
| linux | linux | >= b3e34a47f98974d0844444c5121aaff123004e57 < fbdbf8ac333d3d47c0d9ea81d7d445654431d100 | fbdbf8ac333d3d47c0d9ea81d7d445654431d100 |
| linux | linux | >= b3e34a47f98974d0844444c5121aaff123004e57 < 5bd3c7abeb69fb4133418b846a1c6dc11313d6f0 | 5bd3c7abeb69fb4133418b846a1c6dc11313d6f0 |
| linux | linux | >= b3e34a47f98974d0844444c5121aaff123004e57 < d00dd2f2645dca04cf399d8fc692f3f69b6dd996 | d00dd2f2645dca04cf399d8fc692f3f69b6dd996 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 5.15.87 | 5.15.87 |
| linux | linux_kernel | >= 5.16.0 < 6.0.19 | 6.0.19 |
| linux | linux_kernel | >= 5.19.0 < 6.1.5 | 6.1.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wg2w-8j36-3rqh: In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Fix double-free of elf header buffer
After
b3e34a47f989 ("x86/kexec:
ghsa_unreviewed·2025-12-24
CVE-2023-54146 GHSA-wg2w-8j36-3rqh: In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Fix double-free of elf header buffer
After
b3e34a47f989 ("x86/kexec:
In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Fix double-free of elf header buffer
After
b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"),
freeing image->elf_headers in the error path of crash_load_segments()
is not needed because kimage_file_post_load_cleanup() will take
care of that later. And not clearing it could result in a double-free.
Drop the superfluous vfree() call at the error path of
crash_load_segments().
OSV
x86/kexec: Fix double-free of elf header buffer
osv·2025-12-24
CVE-2023-54146 x86/kexec: Fix double-free of elf header buffer
x86/kexec: Fix double-free of elf header buffer
In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Fix double-free of elf header buffer
After
b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"),
freeing image->elf_headers in the error path of crash_load_segments()
is not needed because kimage_file_post_load_cleanup() will take
care of that later. And not clearing it could result in a double-free.
Drop the superfluous vfree() call at the error path of
crash_load_segments().
OSV
CVE-2023-54146: In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix double-free of elf header buffer After b3e34a47f989 ("x86/kexec: fi
osv·2025-12-24
CVE-2023-54146 CVE-2023-54146: In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix double-free of elf header buffer After b3e34a47f989 ("x86/kexec: fi
In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix double-free of elf header buffer After b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"), freeing image->elf_headers in the error path of crash_load_segments() is not needed because kimage_file_post_load_cleanup() will take care of that later. And not clearing it could result in a double-free. Drop the superfluous vfree() call at the error path of crash_load_segments().
Red Hat
kernel: x86/kexec: Fix double-free of elf header buffer
vendor_redhat·2025-12-24·CVSS 6.4
CVE-2023-54146 [MEDIUM] CWE-763 kernel: x86/kexec: Fix double-free of elf header buffer
kernel: x86/kexec: Fix double-free of elf header buffer
In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Fix double-free of elf header buffer
After
b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"),
freeing image->elf_headers in the error path of crash_load_segments()
is not needed because kimage_file_post_load_cleanup() will take
care of that later. And not clearing it could result in a double-free.
Drop the superfluous vfree() call at the error path of
crash_load_segments().
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel
Debian
CVE-2023-54146: linux - In the Linux kernel, the following vulnerability has been resolved: x86/kexec: ...
vendor_debian·2023
CVE-2023-54146 CVE-2023-54146: linux - In the Linux kernel, the following vulnerability has been resolved: x86/kexec: ...
In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix double-free of elf header buffer After b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"), freeing image->elf_headers in the error path of crash_load_segments() is not needed because kimage_file_post_load_cleanup() will take care of that later. And not clearing it could result in a double-free. Drop the superfluous vfree() call at the error path of crash_load_segments().
Scope: local
bookworm: resolved (fixed in 6.1.7-1)
bullseye: resolved
forky: resolved (fixed in 6.1.7-1)
sid: resolved (fixed in 6.1.7-1)
trixie: resolved (fixed in 6.1.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54146 kernel: x86/kexec: Fix double-free of elf header buffer
bugzilla·2025-12-24
CVE-2023-54146 [MEDIUM] CVE-2023-54146 kernel: x86/kexec: Fix double-free of elf header buffer
CVE-2023-54146 kernel: x86/kexec: Fix double-free of elf header buffer
In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Fix double-free of elf header buffer
After
b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"),
freeing image->elf_headers in the error path of crash_load_segments()
is not needed because kimage_file_post_load_cleanup() will take
care of that later. And not clearing it could result in a double-free.
Drop the superfluous vfree() call at the error path of
crash_load_segments().
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122425-CVE-2023-54146-1510@gregkh/T
Wiz
CVE-2023-54146 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54146 CVE-2023-54146 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54146 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Fix double-free of elf header buffer
After
b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"),
freeing image->elf_headers in the error path of crash_load_segments()
is not needed because kimage_file_post_load_cleanup() will take
care of that later. And not clearing it could result in a double-free.
Drop the superfluous vfree() call at the error path of
crash_load_segments().
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS)
https://git.kernel.org/stable/c/4c71a552b97fb4f46eb300224434fe56fcf4f254https://git.kernel.org/stable/c/554a880a1fff46dd5a355dec21cd77d542a0ddf2https://git.kernel.org/stable/c/5bd3c7abeb69fb4133418b846a1c6dc11313d6f0https://git.kernel.org/stable/c/d00dd2f2645dca04cf399d8fc692f3f69b6dd996https://git.kernel.org/stable/c/fbdbf8ac333d3d47c0d9ea81d7d445654431d100
2025-12-24
Published